vulnerability Check Point Patches Exploited SmartConsole Flaw Allowing Full Admin Access Check Point has released security updates to address a critical vulnerability (CVE-2026-16232) in its SmartConsole login process, which allows unauthenticated remote attackers to gain full administrative access. This fla… The Hacker News · Jul 23, 2026 Critical CVE-2026-16232CVE-2026-62144CVE-2026-62145vulnerabilityauthenticationremote access
threat-intel US Warns of Iranian Hackers Targeting Siemens, Schneider, and Rockwell ICS Devices The US government has issued an updated cybersecurity advisory warning of ongoing Iranian-linked attacks targeting industrial control systems (ICS) manufactured by Siemens, Schneider Electric, and Rockwell Automation. Ha… SecurityWeek · Jul 23, 2026 High IRicsindustrial control systemsplc
threat-intel State Department imposes visa restrictions on foreign cyber scammers The State Department is implementing new visa restrictions targeting individuals involved in foreign cybercrime networks, specifically those linked to scams like sextortion and human trafficking. This follows a broader e… The Record · Jul 23, 2026 High PHCACHcybercrimevisa restrictionssoutheast asia
threat-intel ISC Stormcast For Thursday, July 23rd, 2026 https://isc.sans.edu/podcastdetail/10020, (Thu, Jul 23rd) The ISC Stormcast highlighted a significant increase in malicious email campaigns targeting financial institutions with sophisticated spear-phishing attacks. The campaigns leveraged stolen credentials and a new, highly c… SANS Internet Storm Center · Jul 23, 2026 High phishingspear-phishingcredential-stuffing
threat-intel Ransomware Attack Puts a Chill On Japanese Frozen-Food Chain A ransomware attack targeting Nichirei, a Japanese frozen-food supplier and logistics firm, has disrupted its operations and impacted thousands of clients, including Kentucky Fried Chicken franchises in Japan. Russia-lin… Dark Reading · Jul 23, 2026 High JPransomwaresupply chainjapan
vulnerability Multiples vulnérabilités dans les produits Check Point (23 juillet 2026) Multiple vulnerabilities have been discovered in Check Point products, allowing attackers to elevate privileges and bypass security policies. Check Point reports that CVE-2026-16232 is actively being exploited. Users are… CERT-FR · Jul 23, 2026 High CVE-2026-16232CVE-2026-62144CVE-2026-62145vulnerabilitycheck pointsecurity
vulnerability Multiples vulnérabilités dans Oracle Virtualization (23 juillet 2026) Multiple vulnerabilities have been discovered in Oracle Virtualization, allowing an attacker to compromise data confidentiality, data integrity, and cause a denial of service. These vulnerabilities affect Oracle VM Virtu… CERT-FR · Jul 23, 2026 Medium CVE-2026-47041CVE-2026-47043CVE-2026-47044oraclevirtualizationvulnerabilities
vulnerability Vulnérabilité dans Moodle (23 juillet 2026) A vulnerability in Moodle versions prior to 5.2.1 allows an attacker to compromise user data confidentiality. The CERT-FR has issued a security bulletin detailing the issue and recommending immediate patching. CERT-FR · Jul 23, 2026 Medium moodlevulnerabilitydata breach
vulnerability Multiples vulnérabilités dans Oracle Database Server (23 juillet 2026) Multiple vulnerabilities have been discovered in Oracle Database Server, potentially leading to data integrity compromise, data confidentiality breaches, and remote denial-of-service attacks. These vulnerabilities affect… CERT-FR · Jul 23, 2026 High CVE-2025-7962CVE-2026-28387CVE-2026-28388oracledatabasevulnerability
vulnerability Multiples vulnérabilités dans Oracle Systems (23 juillet 2026) Multiple vulnerabilities have been discovered within Oracle Systems, potentially allowing attackers to compromise data confidentiality, integrity, and cause denial of service. These vulnerabilities affect various Oracle… CERT-FR · Jul 23, 2026 High CVE-2026-60659CVE-2026-60661CVE-2026-60833oraclevulnerabilitypatch
vulnerability Multiples vulnérabilités dans Oracle PeopleSoft (23 juillet 2026) Multiple vulnerabilities have been discovered in Oracle PeopleSoft, allowing an attacker to cause a denial-of-service, lead to data confidentiality breaches, and compromise data integrity. These vulnerabilities are part… CERT-FR · Jul 23, 2026 High CVE-2025-55130CVE-2025-55131CVE-2025-55132oraclepeoplesoftvulnerability
vulnerability Multiples vulnérabilités dans les produits Mitel (23 juillet 2026) Multiple vulnerabilities have been discovered in Mitel products, allowing attackers to execute arbitrary code remotely and inject malicious code via XSS. These vulnerabilities affect various versions of MiCollab and Open… CERT-FR · Jul 23, 2026 High vulnerabilityremote code executionxss
vulnerability Multiples vulnérabilités dans Oracle Java SE (23 juillet 2026) Multiple vulnerabilities have been discovered in Oracle Java SE, potentially allowing an attacker to cause a denial of service, compromise data confidentiality, and damage data integrity. These vulnerabilities affect var… CERT-FR · Jul 23, 2026 High CVE-2026-41254CVE-2026-46917CVE-2026-46968javavulnerabilitysecurity
vulnerability Multiples vulnérabilités dans Oracle Weblogic (23 juillet 2026) Multiple vulnerabilities have been discovered in Oracle WebLogic, allowing an attacker to compromise data confidentiality and integrity. These vulnerabilities affect various WebLogic Server Proxy Plug-ins and the WebLogi… CERT-FR · Jul 23, 2026 High CVE-2025-68161CVE-2026-34477CVE-2026-34478oracleweblogicvulnerability
vulnerability Multiples vulnérabilités dans Oracle MySQL (23 juillet 2026) Multiple vulnerabilities have been discovered in Oracle MySQL, allowing an attacker to cause a denial-of-service, compromise data confidentiality, and damage data integrity. These vulnerabilities are present across vario… CERT-FR · Jul 23, 2026 High CVE-2025-68161CVE-2026-46936CVE-2026-47008mysqloraclevulnerability
vulnerability Multiples vulnérabilités dans Mozilla Thunderbird (23 juillet 2026) Mozilla Thunderbird contains multiple vulnerabilities that could lead to data compromise, security policy bypass, denial of service, remote code execution, and privilege escalation. These vulnerabilities are present in v… CERT-FR · Jul 23, 2026 High CVE-2026-14899CVE-2026-15718CVE-2026-15719vulnerabilitysecurityfirefox
vulnerability Flaws in Passkey Implementation Show Old Attacks Still Work Researchers at SpecterOps discovered several exploitable flaws in Microsoft's passkey implementation, particularly within Microsoft Entra ID, that could allow attackers to impersonate privileged users and bypass MFA. Des… Dark Reading · Jul 22, 2026 High CVE-2026-34348passkeyswebauthnmicrosoft
threat-intel OpenAI scored an own goal with Hugging Face attack, showing how open Chinese models are winning OpenAI is facing scrutiny after a Chinese AI model developer, Hugging Face, reported an attack where malicious code was injected into their systems. This incident highlights the growing competition between Western and Ch… The Register · Jul 22, 2026 Medium CHUSaiopen-sourcesecurity
threat-intel Smashing Security podcast #477: How 14 orders of chicken McNuggets helped nail a suspected Russian hacker This Smashing Security podcast episode explores a significant cyberattack targeting the Netherlands National Police Force, attributed to a Russian-backed hacking group known as Void Blizzard. The attack involved stealing… Graham Cluley · Jul 22, 2026 High NEUKNAcyberattackintelrussian
threat-intel Swiss train maker Stadler refuses Everest $12 million ransomware demand Swiss train manufacturer Stadler Rail refused a $12.3 million ransomware demand from the Russian-speaking group Everest after cybercriminals stole technical data from a supplier’s file-sharing platform. The incident did… The Record · Jul 22, 2026 High SWRUransomwaredata breachsupply chain